Junglewise Threat Intelligence

CVE-2026-15366: vivo Kids Mode access control defect in photo viewer

CVE-2026-15366 · Severity: info · CVSS 3.5 · Published 2026-08-26

Vendors: Vivo.

Executive brief

vivo Kids Mode is a parental control feature that restricts what children can access on their devices. A logic defect in the photo gallery component allows users to bypass these controls and view local photos that should be restricted, potentially exposing users to unintended content.

Technical details

A control logic defect in a built-in webpage of vivo Kids Mode allows unauthorized access to local gallery photos. The vulnerability enables users to view photos directly within the Kids Mode interface, bypassing intended access restrictions. This is an access control bypass affecting Kids Mode versions below 4.9.7.0, which is the fixed version. The vulnerability requires physical access (AV:P) and has no prerequisites for authentication or user interaction. An attacker can view restricted photo content, with limited impact on confidentiality and integrity.

Affected products

  • vivo Kids Mode below 4.9.7.0

Timeline

  • 2026-08-26: disclosed
  • 2026-08-26: patched: Fixed in Kids Mode 4.9.7.0

References

Related threats